Project

General

Profile

Activity

From 05/19/2013 to 06/17/2013

06/17/2013

10:19 PM Bug #3049 (Resolved): RAM Disk RRD Loss Vulnerability

When using the RAM disk option for /tmp and /var, after a reboot and RRD data is restored, the RRD backup file /cf...
NOYB NOYB
03:06 PM Feature #3048 (Resolved): Pre-download packages to reduce downtime during upgrade process?
Not sure if this is possible under the current system...
If it is possible to determine what version of [a] package[...
Adam Thompson
01:11 PM Bug #3047: IPSEC remote access broken in 2.03
As before, same with IOS. Robert Holmes
12:47 PM Bug #3047: IPSEC remote access broken in 2.03
Cisco VPN client is known to be broken when connecting to pfSense (and it's a violation of their license to do so usi... Jim Pingle
12:41 PM Bug #3047: IPSEC remote access broken in 2.03
I don't understand why it doesn't work for me in 2.03 - no config changes whatsoever between 2.02 and 2.03. I also j... Robert Holmes
12:22 PM Bug #3047: IPSEC remote access broken in 2.03
I used your exact IPsec config (aside from fixing the lifetimes to match the documented suggested values), and I am a... Jim Pingle
10:15 AM Bug #2928: Authentication attempts against multiple radius servers should stop when the first reject is received.
For two factor authentication , you need to use Access-Challenge response from your radius server, and use it to proc... Tuyan Ozipek
09:25 AM Bug #3045: NTPD crash / doesn't come up
OK it's started now. I had to go Services - NTP - press Save button. Then press the restart service button. Now it's ... B H
09:22 AM Bug #3045: NTPD crash / doesn't come up
After this procedure i can't start the NTPD service. B H
09:16 AM Bug #3045: NTPD crash / doesn't come up
I've built ntpd binaries with debug symbols, there are binaries for 2.0.3 and 2.1, i386 and amd64:
ntpd-2.0.3-amd64
...
Renato Botelho
03:33 AM Bug #3045: NTPD crash / doesn't come up
Crashed again. File attached. B H
06:53 AM Bug #706: OpenVPN client export needs to include remote-cert-tls server
Hmm, nevermind, it seems to include 'ns-cert-type server' nowadays, that should suffice. Mike Noordermeer
06:46 AM Bug #706: OpenVPN client export needs to include remote-cert-tls server
Nowadays Pfsense seems to be able to generate server certificates, so I don't see any reason to not add 'remote-cert-... Mike Noordermeer

06/16/2013

08:08 PM Bug #3024: need a pipe / flowset / sched number
Another detail is that when the error happens it creates a single limit like the follow.
Limiters:
00001: 262.140...
Alberto Palau
05:14 PM Bug #3047: IPSEC remote access broken in 2.03
You should have enough to re-create it on a pfSense box, but attached is the info you requested. Also, when the VPN ... Robert Holmes
12:20 PM Bug #3047: IPSEC remote access broken in 2.03
Still not enough information. Most importantly we need the IPsec log entries (I forgot to mention that previously) fr... Jim Pingle
11:33 AM Bug #3047: IPSEC remote access broken in 2.03
Forum link is here: http://forum.pfsense.org/index.php/topic,62209.msg341320.html
I didn't get any feedback so I ope...
Robert Holmes
10:58 AM Bug #3047 (Feedback): IPSEC remote access broken in 2.03
There is not nearly enough information here for a valid bug report. Include details about your exact config (every op... Jim Pingle
10:50 AM Bug #3047 (Closed): IPSEC remote access broken in 2.03
In pfSense 2.0 through 2.02, my configuration for remote IPSEC access (like my iPhone) worked fine. IPSEC with Mobil... Robert Holmes
01:39 PM Bug #3045: NTPD crash / doesn't come up
I'm also seeing this every couple of days and have also attached file. David Williams

06/15/2013

10:35 AM Bug #3045: NTPD crash / doesn't come up
The file is attached. B H
01:12 AM Bug #3045: NTPD crash / doesn't come up
If anyone tells me where the ntpd core crash dump is located, sure. B H

06/14/2013

08:07 PM Bug #3046 (Resolved): Fatal error: Call to undefined function get_interface_ip() in /usr/local/captiveportal/radius_authentication.inc on line 56
When using Radius authentication I get this immediately after logging in. My password is accepted, then I receive an... orangepeel beef
04:32 PM Bug #3043 (Rejected): Changing CARP vhid breaks SNAT on the virtual IP
not true except where it causes problems with an upstream ARP cache, which we can't do anything about. Disable/enable... Chris Buechler
12:46 AM Bug #3043 (Rejected): Changing CARP vhid breaks SNAT on the virtual IP
Two nodes with CARP outside and CARP inside.
Outbound SNAT is done via the outside virtual IP.
Changing the vhid of...
Todor K
02:50 PM Bug #3034: Security FLAW in pfSense Wireless Found
Applied in changeset commit:664f9f3b919f970fb77c66cc4c5c3445081d5f25. Renato Botelho
02:40 PM Bug #3034: Security FLAW in pfSense Wireless Found
Applied in changeset commit:2ca432514e09e5388f1786f0f6c6d977d3254533. Renato Botelho
02:40 PM Bug #3034 (Feedback): Security FLAW in pfSense Wireless Found
Applied in changeset commit:df78d8cc1890f19702e3e78bb3c5a583ada52356. Renato Botelho
01:50 PM Bug #3037: Unable to delete PRIQ queues
Applied in changeset commit:c9322c5ceb272a3b51a4cd2f737d268cde3584c7. Renato Botelho
01:50 PM Bug #3037 (Feedback): Unable to delete PRIQ queues
Applied in changeset commit:a22537c73c6a1301b9e2656bfaa4382b93314a55. Renato Botelho
12:26 PM Bug #3045: NTPD crash / doesn't come up
Is there a ntpd core with crash dump that you can share? It could help us to identify the issue. Renato Botelho
11:11 AM Bug #3045 (Resolved): NTPD crash / doesn't come up
The NTP services crashes a lot, reason unknown for me.
The System Logs says:
_kernel: pid 35663 (ntpd), uid 0: ex...
B H
11:02 AM Bug #3044: SSHD failed to start.
http://forum.pfsense.org/index.php/topic,63435.0.html Basel G.
08:59 AM Bug #3044 (Rejected): SSHD failed to start.
Not enough information here. Please post in the forum for assistance in finding the cause of the error. If a legitima... Jim Pingle
06:11 AM Bug #3044 (Rejected): SSHD failed to start.
php: : The command '/usr/sbin/sshd' returned exit code '1', the output was 'Could not load host key: /etc/ssh/ssh_hos... Basel G.

06/13/2013

03:39 PM Bug #2882: 6RD not working in latest snapshots
Hi Ermal
Here is the output of the 2 commands you asked me to run on my Jan 18th build where 6RD works:
http://...
Will Wainwright
01:24 PM Bug #2882: 6RD not working in latest snapshots
And that seemed to have been a user error on my part.
My IPv6 firewall rule on LAN had default (ipv4 dhcp) gateway...
Captain Haddock
01:14 PM Bug #2882: 6RD not working in latest snapshots
Ermal Luçi wrote:
> You are talking about tracking interfaces or 6rd tunnel here?
>
> radvd has nothing to do wit...
Captain Haddock
11:51 AM Bug #2882: 6RD not working in latest snapshots
Will Wainwright wrote:
> Hi Chris,
>
> I'm sorry to report that it has not fixed the issue for me.
>
> As alwa...
Ermal Luçi
11:51 AM Bug #2882: 6RD not working in latest snapshots
You are talking about tracking interfaces or 6rd tunnel here?
radvd has nothing to do with 6rd in this ticket.
...
Ermal Luçi
07:49 AM Bug #2882: 6RD not working in latest snapshots
This was seen in log after reboot:
Jun 13 13:29:23 radvd[49436]: resuming normal operation
Jun 13 13:29:23 radvd[...
Captain Haddock
07:47 AM Bug #2882: 6RD not working in latest snapshots
I just tried this out on:
2.1-RC0 (amd64)
built on Wed Jun 12 18:24:47 EDT 2013
FreeBSD 8.3-RELEASE-p8
Afte...
Captain Haddock
03:24 PM Bug #3042: CARP interface handling
This seems like bad news. PfSense with the current carp interface-based failover seemed like an excellent way to do t... Jupiter Vuorikoski
03:10 PM Bug #3042: CARP interface handling
Also newcarp in FreeBSD 10.x does away with the interface notion entirely so I'm not sure it's a viable request for t... Jim Pingle
03:09 PM Bug #3042: CARP interface handling
It's too late for more 2.1 features, removing 2.1 target. Jim Pingle
03:08 PM Bug #3042 (Closed): CARP interface handling
Currently PfSense handles carp interfaces as Layer 3 interfaces with a static IP-address on the created interface. Ho... Jupiter Vuorikoski
02:18 PM Bug #2526: Limiter appears to break IPv6 connectivity
This problem appears to be present in the Wed Jun 12 06:19:03 EDT 2013 build. IPv6 Traffic hits the limiter as shown ... Alex Fox
12:40 PM Bug #3008: custom dynamic dns update with https - curl error
Applied in changeset pfsense-tools:commit:3e217b8208cdba17060a72a9ccb5fb7ebff9ed25. Renato Botelho
12:30 PM Bug #3008: custom dynamic dns update with https - curl error
Applied in changeset pfsense-tools:commit:9c0a39f717a04def5d6c0260eb74a7cd0cde8b17. Renato Botelho
11:30 AM Feature #687 (Resolved): Test Button for Growl Notifications
Implemented in commit:48b86f6257bd0c79f26ee5e111bfa1488a28e6fb Jim Pingle
11:29 AM Todo #1139 (Resolved): Email notification test button
Implemented in commit:48b86f6257bd0c79f26ee5e111bfa1488a28e6fb Jim Pingle
10:17 AM Bug #3041 (Rejected): PHP Fatal error: Allowed memory size of 268435456 bytes exhausted
Not enough information here for a valid bug report. Please post in the forum where someone can assist you in diagnosi... Jim Pingle
10:15 AM Bug #3041 (Rejected): PHP Fatal error: Allowed memory size of 268435456 bytes exhausted
Crash report begins. Anonymous machine information:
amd64
8.3-RELEASE-p8
FreeBSD 8.3-RELEASE-p8 #1: Wed Jun 12 ...
Alberto Palau
09:49 AM Feature #2757: CDP/ISDP/LLDP support.
Yeah! It would be great to have CDP in pfsense! Todor K

06/12/2013

10:20 PM Bug #2882: 6RD not working in latest snapshots
Hi Chris,
I'm sorry to report that it has not fixed the issue for me.
As always, please let me know if there's ...
Will Wainwright
01:08 AM Bug #2882: 6RD not working in latest snapshots
confirmed working for me again on the latest snapshot. Will leave this as is for feedback from others for now. Chris Buechler
02:12 PM Feature #3040 (Closed): User friendly firewall log reading
Most of that is already done in 2.1's firewall log view/filtering. The ones that aren't there yet aren't really feasi... Jim Pingle
01:59 PM Feature #3040 (Closed): User friendly firewall log reading
It would be great if the firewall logs could be more debug-friendly:
- have source and destination ports in separate...
Todor K
12:48 PM Bug #3039: New vouchers doesn't sync with CARP slave
Yup, I thought it could be scheduled somehow, but it didn't happen in the next few hours. Todor K
12:45 PM Bug #3039: New vouchers doesn't sync with CARP slave
This is not immediate.
You are sure that you waited enough for the replication to happen?
Ermal Luçi
11:12 AM Bug #3039 (Resolved): New vouchers doesn't sync with CARP slave
Issuing new vouchers on master node is not automatically synced with CARP slave node.
When I go to Services>Captive ...
Todor K
12:16 PM Bug #3015 (Resolved): DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Renato Botelho
12:10 PM Bug #3035 (Rejected): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
It's the expected behaviour, if you don't have zones, status menu won't show up. Renato Botelho
11:01 AM Bug #3038 (Resolved): CARP master not stopping slave's Captive portal
Having CARP active with two nodes, when I start Captive service on master it starts it on the slave node too.
But st...
Todor K

06/11/2013

02:08 PM Bug #2882 (Feedback): 6RD not working in latest snapshots
should work with tomorrow's snapshot. Chris Buechler
01:55 PM Bug #3037 (Resolved): Unable to delete PRIQ queues
If you use PRIQ, you cannot delete any queues, even ones that were created manually. The delete button does not appea... Jim Pingle
11:42 AM pfSense Packages Bug #3036 (Resolved): Small web interface bug
Hi there!
That's my first bug report and I hope it's well done :)
Services>Snort
Add or edit interface>Alert Set...
Todor K
10:15 AM Bug #3020: HFSC Priority
Heh that is just a copy/pasto from implementation.
Will probably fix that.
Ermal Luçi

06/10/2013

06:56 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I just tested this again on a fresh OVA. I found that starting from a fresh install (i.e. no zones), creating a zone,... Christian McDonald
03:47 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
it shouldn't show up anywhere when there are no zones defined, I've noticed that changed in 2.1. In 2.0.x and previou... Chris Buechler
03:32 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I can only reproduce that when I have no zones defined. If I have a zone defined, it always shows up for me. Jim Pingle
03:30 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
Christian McDonald wrote:
> I can reproduce this on two pfSense boxes each running:
>
> 2.1-RC0 (amd64)
> built...
Renato Botelho
11:06 AM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
I can reproduce this on two pfSense boxes each running:
2.1-RC0 (amd64)
built on Thu Jun 6 21:08:57 EDT 2013
Christian McDonald
06:28 AM Bug #3035 (Feedback): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
Not reproducible here, as you can see on attached screenshot. Renato Botelho
06:47 AM Bug #3026 (Rejected): not all interfaces will get their designated IP after I add an IP to an interface
Seems like a local issue, I could not reproduce. You should try to get help on forums and mailing lists to try to fig... Renato Botelho
06:30 AM Bug #3034: Security FLAW in pfSense Wireless Found
What is the length of the password you got the issue? Renato Botelho

06/09/2013

10:27 PM Bug #3035: [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
!http://i.imgur.com/SgaFqaO.png! Christian McDonald
10:24 PM Bug #3035 (Rejected): [Satus->Captive Portal] Menu Link Disappears When Viewing Captive Portal Status
When viewing the Captive Portal Status, the menu item for Status->Captive Portal Disappears
Steps to reproduce:
...
Christian McDonald
06:43 PM Bug #3034 (Resolved): Security FLAW in pfSense Wireless Found
I have found a security flaw in pfSense wireless. If you enable WPA2 for security and use a password for the pre shar... Steven Anderson

06/08/2013

05:08 PM Bug #3033 (Rejected): Static IPv6 route to OpenVPN tunnel ignored
I have an openvpn tunnel to a remote server which works correctly for IPv4 traffic but not for IPv6. When the remote ... Lakin Lowrey
02:18 PM pfSense Packages Bug #3032 (Rejected): last activity in CP 2.0.3
test on 2.1 and report more info on forum if you can still replicate Chris Buechler
03:17 AM pfSense Packages Bug #3032 (Rejected): last activity in CP 2.0.3
hi
in my 2.0.3 amd64 captive portal last activity was periodically (every minutes?) reset to the system boot time:...
Fabio Faro
03:32 AM Bug #2752: Captive Portal Last Activity isn't update anymore --> idle timeout just after login
i have two installation with 2.0.3 but the problem still exist.
i opened a new segnalation (3032)
thx
Fabio Faro

06/07/2013

02:27 PM Bug #3020: HFSC Priority
Ermal Luçi wrote:
> HFSC does not have notion of priority.
Ok, sorry for this report but I Sugere remove or corre...
Julien Bénic
11:35 AM Feature #3031 (Resolved): Message is false after changing Hardware Checksum Offloading setting
It seems that appliance needs to reboot after changing the advanced networking setting.
System -> Advanced, click ...
c vt
11:14 AM Bug #3030 (Resolved): When using LAGG+VLAN+ALTQ, the shaper wizard does not fill in the interface bandwidth
If you are using LAGG+VLAN interfaces (e.g. lagg0_vlan10) in the shaper wizard, the wizard does not fill in the bandw... Jim Pingle
03:17 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Having similar issues:
2.1 RC0 (symptoms started from 2.03 on as far as i can remember)
Policy Generation > Uni...
Peter Borföi
03:12 AM pfSense Packages Bug #999: vhosts does not show up as started
Hi!
Could you tell us how to fix it.
I think two years it's so much time to fix this little problem (talking ab...
Net Vicious

06/06/2013

11:44 PM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
Thanks a lot for your time and sorry for the useless ticket opening. Imrane Dessai
08:45 AM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
IP Alias VIPs don't work that way, but proxy ARP VIPs are not and cannot be compatible in the way you describe.
On...
Jim Pingle
08:43 AM Feature #3025: Allow Proxy Arp to Bind to CARP Interface
Ip Alias can't expand a whole network withing a single line of conf
When configuring a Proxy ARP you can specify a...
Imrane Dessai
08:28 AM Feature #3025 (Rejected): Allow Proxy Arp to Bind to CARP Interface
no need. IP alias or more CARP. Chris Buechler
07:46 AM Feature #3025 (Rejected): Allow Proxy Arp to Bind to CARP Interface
Hi,
We are using a cluster pfSense to NAT 1:1 two network.
I need to make Proxy ARP VIP to bind to CARP Interfa...
Imrane Dessai
04:53 PM Feature #3029 (Resolved): DHCPv6 Server/RA page should list interfaces that are configured to track DHCP-PD
The configuration page for the DHCPv6 server and router advertisements currently only lists those interfaces that hav... Daniel Becker
04:31 PM Bug #3028 (Resolved): Prefix delegation fails to add rules for dhcp6 traffic on tracking (LAN) interface
I notice that configuring DHCP-PD starts a dhcpd server on the tracking (LAN) interface that serves up the delegated ... Daniel Becker
04:01 PM Bug #2412 (Resolved): inbound 6to4 traffic does not work in pf
Ermal Luçi
12:55 PM Bug #2412: inbound 6to4 traffic does not work in pf
I can confirm that this is working as intended. Thank you for fixing it. We are mainly using this to test ipv6 capabi... Richard Adams
02:08 PM Bug #3027 (Resolved): input_errors2Ajax function
In various places input_errors2Ajax() is used. However this function doesn't exist.
I'm assuming the original intent...
Warren Baker
10:22 AM Bug #3026: not all interfaces will get their designated IP after I add an IP to an interface
What you are saying is you go and set a static ip to an interface and the interface didn't get that IP address config... Renato Botelho
09:33 AM Bug #3026 (Rejected): not all interfaces will get their designated IP after I add an IP to an interface
When I add an IP to an interface my pfsense will become unresponsive for a minute.
On Zabbix I can see the system lo...
frater fenantius
03:36 AM Bug #3016 (Resolved): IPsec client (or branch office) can't access to Internet over VPN gateway
Chris Buechler
03:29 AM Bug #3023 (Rejected): Snort + Intel NIC not working on 2.1 RC0
probably promiscuous broken in the 8.3 fxp driver. There's another ticket open to back port a newer driver. Chris Buechler
02:11 AM Bug #1351: Mobile IPsec no traffic pass trough after 2nd connect after 5 minutes
Same problem here running:
2.0.3-RELEASE (amd64)
Client can connect OK for the first session but then after dis...
Ignat Esso

06/05/2013

03:37 PM Bug #3024 (Rejected): need a pipe / flowset / sched number
I am experiencing a bug in the captive portal, it happens every 3 days or so, this ruling requires me to reinstall pf... Alberto Palau
02:54 PM Bug #3023 (Rejected): Snort + Intel NIC not working on 2.1 RC0
I have used Snort + Intel NIC (as WAN interface) successfully on pfSense 2.03 before. I cannot get it to work with 2.... Victor Kwong
11:05 AM Bug #3016: IPsec client (or branch office) can't access to Internet over VPN gateway
Fix looks and works correctly
2.1-RC0 (amd64)
built on Tue Jun 4 20:54:59 EDT 2013
FreeBSD 8.3-RELEASE-p8
Serguei Leontiev
07:48 AM Bug #3022 (Resolved): OpenVPN does not failover to the 2nd configured LDAP auth.server
More details:
http://forum.pfsense.org/index.php/topic,62570.msg337904.html#msg337904
It might be a limitation of...
Alex Kolesnik
07:42 AM Bug #3020 (Rejected): HFSC Priority
HFSC does not have notion of priority. Ermal Luçi
04:27 AM Bug #3020 (Rejected): HFSC Priority
Hi,
The priority range for HFSC is 0 to 7. Priority 0 is the lowest priority for the least important data. When no...
Julien Bénic

06/04/2013

06:46 PM Bug #3019 (Rejected): Realtek 8168 Gigabit Ethernet
no telling whether it's a bug from that, but probably not. Please post to the forum or mailing list for help. Only sp... Chris Buechler
06:35 PM Bug #3019 (Rejected): Realtek 8168 Gigabit Ethernet
I am not sure if this is a bug but you can close this if not.
Whenever I am copying big data from my network to my...
Patrick Vanguardia
08:49 AM Feature #3018 (Resolved): Can't disable autogenerate SPD rules
Checkbox "System->Advanced->Anti-lockout" (Disable webConfigurator anti-lockout rule)
don't affect for spd.conf gene...
Serguei Leontiev
06:30 AM Bug #3016: IPsec client (or branch office) can't access to Internet over VPN gateway
Applied in changeset commit:50d3ed9c3c76d16a88d801ded20f4db9e7f6e915. Renato Botelho
06:30 AM Bug #3016 (Feedback): IPsec client (or branch office) can't access to Internet over VPN gateway
Applied in changeset commit:4eb3ac52b07533c26a1ebf3e496d25669629a038. Renato Botelho

06/03/2013

07:30 AM Bug #3017: Cert Manager - Certificates - + shows "add or import ca" instead of "add or import certificate"
Applied in changeset commit:d4090fbfe00f2cdac17a4f7e8f89a43a6d1728eb. Jim Pingle
07:30 AM Bug #3017: Cert Manager - Certificates - + shows "add or import ca" instead of "add or import certificate"
Applied in changeset commit:6b53736d3beaef6d536bbcaf10b07865fd53248d. Jim Pingle
07:30 AM Bug #3017 (Feedback): Cert Manager - Certificates - + shows "add or import ca" instead of "add or import certificate"
Applied in changeset commit:ae3caa3d83d5d33ab17cf8a4336621d364c051c5. Jim Pingle

06/02/2013

11:58 PM Bug #3017 (Resolved): Cert Manager - Certificates - + shows "add or import ca" instead of "add or import certificate"
System - Cert Manager - Certificates - +
The hovering text shows "add or import ca" (identical to the CA page) inste...
Uni Tronus
10:09 PM Bug #3012: Bug in full backup size computation and/or display
Sorry I meant gzip 1.3.12 Jerome Alet
10:08 PM Bug #3012: Bug in full backup size computation and/or display
Nothing to do with this particular backup file, since the problem is there each time we do a new full backup. Most pr... Jerome Alet
08:21 PM Bug #3012 (Closed): Bug in full backup size computation and/or display
something wrong with that backup file, or maybe with gzip itself. Nothing we can do either way, it does work correctl... Chris Buechler
07:28 PM Bug #3012: Bug in full backup size computation and/or display
... Jerome Alet

06/01/2013

07:38 AM Bug #3016: IPsec client (or branch office) can't access to Internet over VPN gateway
Sorry:
Main office
Mode: tunnel
Local Subnet: 0.0.0.0/0
Remote Subnet: BRANCH-LAN
: cat /var/etc/ipsec/spd.c...
Serguei Leontiev
07:26 AM Bug #3016: IPsec client (or branch office) can't access to Internet over VPN gateway
Don't delete tunnel for main office Serguei Leontiev
07:21 AM Bug #3016 (Resolved): IPsec client (or branch office) can't access to Internet over VPN gateway
Branch office tunnel:
Mode: tunnel
Local Subnet: LAN
Remote Subnet: 0.0.0.0/0
root(1): cat /var/etc/...
Serguei Leontiev
07:32 AM Bug #2919: IPv6 - WAN and LAN (DHCP-PD) does not renew address
I have been testing with m0n0wall (1.8.1b540) and it does not have this problem. Perhaps the teams can collaborate t... David Williams
03:50 AM Bug #3015: DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Thanks for the fast turn around Jim. That fixed it. Gavin J

05/31/2013

08:30 PM Bug #3015: DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Applied in changeset commit:9399370b367df7b73b84d605f4f44599c93b0bbe. Jim Pingle
08:30 PM Bug #3015 (Feedback): DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
Applied in changeset commit:f79a5df0733fe17d4a938381e9175fa2e2abefb1. Jim Pingle
07:10 PM Bug #3015 (Resolved): DHCP (v4) won't start because of IPv6 DNS servers in /var/dhcpd/etc/dhcpd.conf
The process which writes out the /var/dhcpd/etc/dhcpd.conf file just before starting dhcpd is configuring the forward... Gavin J
04:53 PM Feature #3014 (Needs Patch): Add Variomedia to Dyndns providers
Could someone please add Variomedia (german hoster and domain registrar - http://www.variomedia.de) to the Dyndns pro... Klaus Rörig
10:04 AM pfSense Packages Bug #3003 (Rejected): Freeeadius.xml bug
There is no problems with the message
The value MUST NOT be < 60 and it SHOULD be >= 600.
Renato Botelho
09:49 AM pfSense Packages Bug #3003: Freeeadius.xml bug
http://www.ietf.org/rfc/rfc2869.txt
The Value field contains the number of seconds between each
inter...
Alexander Wilke
08:27 AM Bug #3012 (Feedback): Bug in full backup size computation and/or display
Seems there is something wrong with the backup file. I tested it here, GUI says 392.43Mb and I checked the file:
<pr...
Renato Botelho

05/30/2013

06:35 AM Bug #2409: ipfw - entryzerostats
Using latest snaps
when we use Captive portal, RADIUS_ACCOUNTING_STOP packets are not sent to RADIUS server
Vlad Arakin
02:24 AM Bug #1980 (Closed): RFC 2136 will not update two records for one interface
thanks Chris Buechler
12:59 AM Bug #1980: RFC 2136 will not update two records for one interface
Related to #2068. It now works on i386/amd64 on version 2.0.3.
I.e. this can be closed.
Andreas Winge
01:04 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
so is there any solution to this, like an updated driver or so? Bipin Chandra

05/29/2013

04:55 PM Feature #3013 (Resolved): Better upgrading for a CARP cluster
Not sure if this is a bug or something we do incorrectly, so I've added this issue as "Feature".
While upgrading a...
Jerome Alet
04:41 PM Bug #3012: Bug in full backup size computation and/or display
Sorry but how could a 30 GB compressed file be extracted and only consume 640 MB ? If restoring is not complete and i... Jerome Alet
04:35 PM Bug #3012: Bug in full backup size computation and/or display
that's the extracted size, not compressed size. Whether it's better to put the compressed size there I'm not sure, pe... Chris Buechler
04:29 PM Bug #3012 (Closed): Bug in full backup size computation and/or display
We have installed several releases of 2.1 on AMD64 since it's in BETA stage over the course of several months, but th... Jerome Alet
03:31 PM Bug #3011 (Rejected): Mobile client disconnect but SA not flushing
2.1 - 29 may snapshot.
I use a mutual psk+ xauth for mobile clients with Policy Generation on, Proposal Checking obe...
luca cuzzolin
02:43 PM Bug #2303: SPD on secondary not cleared after config sync
I have same problem with 2.0 and 2.1 - 29 may snapshot.
I use a mutual psk+ xauth for mobile clients with Policy Gen...
luca cuzzolin
10:07 AM Bug #2627 (New): Old delegated prefixes are not removed from the LAN interface
Renato Botelho
10:05 AM Bug #2910 (New): monitoring-disabled gateway causes wrong tiered gateway in route-to
Renato Botelho
09:24 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
Starting to look a lot more like mine was modem related. Replaced mine on yesterday afternoon, been up since then.
...
Anonymous
08:50 AM Bug #2979: Increase RRD Max values to account for 10Gbit/s Ethernet
Applied in changeset commit:2bba9aefc21a4e173af3626fb5d08516e35ee47a. Renato Botelho
08:50 AM Bug #2979 (Feedback): Increase RRD Max values to account for 10Gbit/s Ethernet
Applied in changeset commit:fa3b33a57e362654551a16a91a5c6b56971ad4c4. Renato Botelho
07:20 AM Bug #3008: custom dynamic dns update with https - curl error
Applied in changeset pfsense-tools:commit:73eee43c2c60f6ffebd507115bbf3c3908f5e5db. Renato Botelho

05/28/2013

09:30 PM Bug #1553: Dynamic DNS does not allow @ in the password
I placed pull request 656 on git to resolve this issue, by using "rawurlencode":... Andrew DeFilippis
10:18 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
I managed to reproduce it locally with an ALIX board and can confirm the issue is related to vr driver. It's always r... Renato Botelho
05:44 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
I think my issue may be modem related. I thought I had ruled this out but it seems both modems I tested with gave iss... Anonymous
09:22 AM Feature #1855: NAT before IPsec VPN
This is tested and working in several production networks, there are no confirmed issues currently. Please post in th... Jim Pingle
08:59 AM Feature #1855: NAT before IPsec VPN
Hi!
I have a same problem as Michele Di Maria. - Please reopen a ticket.
Dalm Tian
04:45 AM Bug #3004: config upgrade code needs to change VIP binding on IPsec
Ermal Luçi wrote:
> [...]
>
> Seems the [^_] is wrong here it is not present on earlier versions there, no?
[^...
Renato Botelho
03:09 AM Bug #3004: config upgrade code needs to change VIP binding on IPsec
... Ermal Luçi
03:57 AM Bug #2984: IPSec adds route but isn't needed any more
something to be re-evaluated in the future. Chris Buechler
03:53 AM Bug #2984: IPSec adds route but isn't needed any more
I wouldn't make this removed.
The problem is that reply-to/route-to are dynamic based on gateway status.
While stat...
Ermal Luçi
03:51 AM Bug #2993: IPsec in transport mode, tunneled traffic does not flow through enc0
I will take a look at seeing if can make this less tricky. Ermal Luçi
03:50 AM Bug #2999 (Feedback): sticky connections are really, really broken w/relayd
Applied in changeset pfsense-tools:commit:eae00391a109101fc995d3309a6e2d2bdb7be579. Ermal Luçi
03:43 AM Bug #2999: sticky connections are really, really broken w/relayd
that's not how it's ever worked before, it's stayed sticky to a specific rdr in every previous OS version. Chris Buechler
03:38 AM Bug #2999: sticky connections are really, really broken w/relayd
Actually fixed.
I had disabled the per rule src-tracking to mitigate something else.
Though seems it hurts more than ...
Ermal Luçi
03:34 AM Bug #3008 (Feedback): custom dynamic dns update with https - curl error
Please test with new snapshots or gitsync Ermal Luçi
03:05 AM Bug #3008: custom dynamic dns update with https - curl error
Probably just a rebuild of ca_root_nss port is needed on the snapshot builder!
Try to fetch from here http://ftp.f...
Ermal Luçi
03:30 AM Bug #3001: Captive portal Voucher sync on HTTPS with custom port
Applied in changeset commit:368d34c31aed69fe5f0c44814367a2658f4b4bc0. Ermal Luçi
03:30 AM Bug #3001 (Feedback): Captive portal Voucher sync on HTTPS with custom port
Applied in changeset commit:f9d480ff0b4a0cbd569a600ba6087770226ddba5. Ermal Luçi

05/27/2013

03:58 PM Bug #3009 (Rejected): Package Manager does not work after updating
This is not a general issue, but typically specific to a certain package being installed. Post on the forum for assis... Jim Pingle
01:02 PM Bug #3009 (Rejected): Package Manager does not work after updating
Updated to 2.1-RC0 (i386) built on Sun May 26 19:31:39 EDT 2013. The Package Manager page showed message that package... Anonymous
03:57 PM Bug #3010 (Rejected): DC ethernet driver seems to have issues with some multiport card and mother board combinations
There really isn't anything we can do about that. Raise it as a FreeBSD PR if you can reproduce it on a stock FreeBSD... Jim Pingle
03:37 PM Bug #3010 (Rejected): DC ethernet driver seems to have issues with some multiport card and mother board combinations
Greetings,
On some mother boards, with multiport 21143 based NIC cards, there seem to be driver problems. Symptoms...
Clif Cox
09:42 AM Bug #3004 (Feedback): config upgrade code needs to change VIP binding on IPsec
There is already a function to do it, upgrade_085_to_086. I tested it locally and it worked as expected.
If you ha...
Renato Botelho
06:32 AM Bug #3008 (Resolved): custom dynamic dns update with https - curl error
Hello,
using HTTPS-Urls with Dynamic DNS gives the following error and no update is done....
Klaus Rörig
01:59 AM Feature #3007 (Resolved): "protocol" field in rules does not support selection of protocol 41 (used by GIF tunnels)
I would like to be able to include traffic that leaves over a GIF tunnel in my traffic shaping for the physical inter... Daniel Becker

05/26/2013

11:42 AM Bug #2409: ipfw - entryzerostats
Upgrade to 2.0.3-RELEASE - bug confirmed:
ipfw table 1 entryzerostats 10.0.0.83
ipfw: getsockopt(IP_FW_TABLE_ZERO_E...
Vlad Arakin

05/25/2013

12:53 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
so i believe its not drivers coz it cant be affecting different brands so the next thing that comes to my mind is net... Bipin Chandra

05/24/2013

02:51 PM Bug #3006 (Resolved): filterdns prevents pfsense to boot up when dns resolution is not possible.
If dns resolution is not possible (like wan interface is down), it takes too much time for filterdns to timeout durin... Tuyan Ozipek
09:18 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
Bipin Chandra wrote:
> im suffering it on a alix which has via chipset, mayb others can mention theirs to be sure it...
Anonymous
09:11 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
im suffering it on a alix which has via chipset, mayb others can mention theirs to be sure its via drivers because to... Bipin Chandra
06:38 AM Bug #1943: PPPoE won't reconnect after link loss when using vr(4) NICs on certain ISPs only
This issue is starting to drive me a bit crazy.
I have multiwan set up with 2 x dsl PPPoE connections and a ppp 3g...
Anonymous
06:20 AM Bug #3005: cant delete or edit unknown CAs and certificate (orphan entries)
ok figured it out, there were one left over <cert/> and <ca/> tag before the actual ones with valid entries, removed ... Bipin Chandra
05:58 AM Bug #3005: cant delete or edit unknown CAs and certificate (orphan entries)
no idea how it got there but in older snaps etc i used to use SSH so it might have generated that time and when i sto... Bipin Chandra
05:56 AM Bug #3005: cant delete or edit unknown CAs and certificate (orphan entries)
i checked the config file and i cant seem to find it in config file but it shows on my cert list on the gui.
the c...
Bipin Chandra
05:07 AM Bug #3005: cant delete or edit unknown CAs and certificate (orphan entries)
How did they get there?
We'll need to see a copy of the relevant portions of your config.xml not just screenshots.
Jim Pingle
04:16 AM Bug #3005 (Resolved): cant delete or edit unknown CAs and certificate (orphan entries)
im on latest nanobsd of 2.1-RC0 (i386) and not able to delete orphan CA and certificate entries,s creenshots attached Bipin Chandra

05/23/2013

07:34 PM Bug #3004 (Resolved): config upgrade code needs to change VIP binding on IPsec
In 2.0.x when you have an IPsec connection bound to a CARP IP, its interface is set as something like: ... Chris Buechler
06:10 AM Bug #2941: Prohibit adding aliases containing FQDNs in static routes
Applied in changeset commit:f0867239c1b15c711ea3c6eefd896c2d2aaefcae. Renato Botelho
06:10 AM Bug #2941: Prohibit adding aliases containing FQDNs in static routes
Applied in changeset commit:5e2df7fc1c71c2e876e8eb1f99f7b3c8419ea72c. Renato Botelho

05/22/2013

08:22 PM Feature #1663 (Resolved): DHCPv6 relay
Chris Buechler
08:21 PM Feature #1492 (Resolved): Captive Portal Interim Updates
Chris Buechler
08:19 PM Bug #2326 (Closed): Erroneous successful webGUI authentication with blank password and AD authentication backend
Chris Buechler
08:19 PM Bug #2764 (Resolved): Captive Portal Voucher Sync issue
Chris Buechler
08:17 PM Bug #2978 (Closed): Broken URL table
the one problem noted here is fixed, URL tables in general work fine. Greg if you have any specific info on replicati... Chris Buechler
08:15 PM Bug #2901 (Closed): Traffic shaper error results in blocked traffic
no shaper config there, no response, no other such reports of problems. Chris Buechler
02:28 AM pfSense Packages Bug #3003 (Rejected): Freeeadius.xml bug
freeradius.xml line have a bug
<description><![CDATA[Enter the seconds which should be between every interim-update....
N.Selim GUNER

05/21/2013

06:22 PM Feature #1009: Active Directory group membership checking
Pi Ba wrote:
>
> ...
>
> Im not sure if this would mean this issue can already be closed.?..
> Anyway thanks f...
George C
02:35 PM pfSense Packages Bug #3002 (Rejected): Open VPN TLS Error
This is a configuration issue. Please use the forum for support. Jim Pingle
02:26 PM pfSense Packages Bug #3002 (Rejected): Open VPN TLS Error
I have a fresh install pfsense 2.0.3-RELEASE (i386) built on Fri Apr 12 10:22:21 EDT 2013 FreeBSD 8.1-RELEASE-p13
I...
Daniel Bouariu
12:04 PM Bug #1974: Captive Portal RADIUS accounting bytes wrong
Allan Stanley wrote:
> Testing in the 2.0.3 release and it seems to work fine.
> I last tested it in 2.1 beta a mo...
Allan Stanley
12:03 PM Bug #1974: Captive Portal RADIUS accounting bytes wrong
Be sure to include your architecture (amd64 or i386) when reporting, that can make a difference. Jim Pingle
11:48 AM Bug #1974: Captive Portal RADIUS accounting bytes wrong
Testing in the 2.0.3 release and it seems to work fine.
I last tested it in 2.1 beta a month or so ago and it over ...
Allan Stanley
09:24 AM Bug #1974 (New): Captive Portal RADIUS accounting bytes wrong
Recent comments indicate this is still an issue. Jim Pingle
04:51 AM Bug #3001 (Resolved): Captive portal Voucher sync on HTTPS with custom port
Voucher sync between 2 pfSense instances using webGUI HTTPS with custom port (Ex. 33333) is not working. ... Zoltan Lukacs
04:30 AM Bug #2999 (Resolved): sticky connections are really, really broken w/relayd
Sticky connections in combination with relayd in 2.1 is seriously broken. Take this circumstance, relayd listening on... Chris Buechler

05/20/2013

02:42 AM Bug #1629: invalid state table entries after WAN IP change
When we have a state like this :... Tom De Coninck

05/19/2013

08:22 PM Bug #2998 (Resolved): Diffserv Code Point options misleading
In pfsense 2.1 beta1, on the Firewall -> Rules -> Edit page there's an option for "Diffserv Code Point". This is a dr... Adam Gensler
 

Also available in: Atom